Email Header Analyzer

Security REST API MCP

Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop delays, SPF/DKIM/DMARC results, every public IP seen, and suspicious-routing flags.

This page documents the HTTP endpoint POST /api/tools/email-header-analyzer/execute. See the MCP reference →

Call it over REST

POST https://api.findutils.com/api/tools/email-header-analyzer/execute · no API keys · 60 requests/min per IP

Execute — verified arguments

curl -X POST https://api.findutils.com/api/tools/email-header-analyzer/execute \
  -H "Content-Type: application/json" \
  -d '{
    "headers": "Received: from a.example.com (a.example.com [203.0.113.9]) by mx.example.org; Tue, 18 Aug 2026 10:00:02 +0000\nAuthentication-Results: mx.example.org; spf=pass; dkim=pass; dmarc=pass\nFrom: [email protected]\nTo: [email protected]\nSubject: Hello\nDate: Tue, 18 Aug 2026 10:00:00 +0000\nMessage-ID: <[email protected]>"
  }'

Parameter schema for this endpoint

curl https://api.findutils.com/api/tools/email-header-analyzer

Interactive docs · OpenAPI 3.1 spec · All REST tools

Input schema

Argument Type Required Description
headers string yes The raw email headers (the "Show original" / "View source" block), including every Received: line.

Example arguments (verified)

{
  "headers": "Received: from a.example.com (a.example.com [203.0.113.9]) by mx.example.org; Tue, 18 Aug 2026 10:00:02 +0000\nAuthentication-Results: mx.example.org; spf=pass; dkim=pass; dmarc=pass\nFrom: [email protected]\nTo: [email protected]\nSubject: Hello\nDate: Tue, 18 Aug 2026 10:00:00 +0000\nMessage-ID: <[email protected]>"
}

Also an MCP tool

Claude, Cursor, and any MCP client can call this tool as findutils:email_header_analyzer after one connect command.

Connect once

claude mcp add findutils --transport http https://mcp.findutils.com/
Open the MCP reference for Email Header Analyzer →

More Security tools